Share this article:

How should HR address 'GDPR' training?

How should HR address 'GDPR' training?
How should HR address 'GDPR' training?

Under incoming GDPR legislation, organisations will have to educate staff on their responsibilities in complying with the new regulations.

The Information Commissioner’s Office (ICO) advises that businesses should “implement appropriate technical and organisational measures that ensure and demonstrate that you comply. This may include internal data protection policies such as staff training, internal audits of processing activities, and reviews of internal HR policies.”

However, according to IT Governance’s 2017 GDPR Report, less than ten per cent of organisations have provided GDPR staff awareness training to all employees. The report also showed that only 53% of organisations are planning to provide GDPR staff awareness training in the future.

Considering that most breaches are the fault of human error, caused by careless actions such as leaving a company laptop on a train, accidentally sending data to the wrong email address or opening a phishing email; it’s paramount staff know how to reduce risk. Especially considering that a data breach can result in a sum of up to £500,000, with potential sanctions for non-compliance rising to €20 million, or four per cent annual global turnover.

Subscribe now to myGrapevine+ and get access to our comprehensive knowledge portal.


Already a subscriber?Sign in

Welcome Back